Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
82 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 5.3% | — | Siemens Simatic PCS 7Siemens Simatic Pcs7Siemens Simatic TiaportalSiemens Simatic Wincc | 26/11/2014 | 17/6/2026 | The WinCC server in Siemens SIMATIC WinCC 7.0 through SP3, 7.2 before Update 9, and 7.3 before Update 2; SIMATIC PCS 7 7.1 through SP4, 8.0 through SP2, and 8.1; and TIA Portal 13 before Update 6 allows remote attackers to execute arbitrary code via crafted packets. | |
| Modificada | Media (5) | 2.1% | — | Siemens Simatic Wincc Open Architecture | 7/2/2014 | 17/6/2026 | Siemens SIMATIC WinCC OA before 3.12 P002 January allows remote attackers to cause a denial of service (monitoring-service outage) via malformed HTTP requests to port 4999. | |
| Modificada | Media (5) | 3.5% | — | Siemens Simatic Wincc Open Architecture | 7/2/2014 | 17/6/2026 | Directory traversal vulnerability in Siemens SIMATIC WinCC OA before 3.12 P002 January allows remote attackers to read arbitrary files via crafted packets to TCP port 4999. | |
| Modificada | Alta (7.5) | 5.3% | — | Siemens Simatic Wincc Open Architecture | 7/2/2014 | 17/6/2026 | The integrated web server in Siemens SIMATIC WinCC OA before 3.12 P002 January allows remote attackers to execute arbitrary code via crafted packets to TCP port 4999. | |
| Modificada | Media (5) | 1.7% | — | Siemens Simatic Wincc Open Architecture | 7/2/2014 | 17/6/2026 | Siemens SIMATIC WinCC OA before 3.12 P002 January uses a weak hash algorithm for passwords, which makes it easier for remote attackers to obtain access via a brute-force attack. | |
| Modificada | Alta (9.3) | 7.1% | — | Siemens Simatic Wincc Flexible RuntimeSiemens Simatic Wincc Runtime | 16/9/2011 | 16/6/2026 | Heap-based buffer overflow in the Siemens WinCC Runtime Advanced Loader, as used in SIMATIC WinCC flexible Runtime and SIMATIC WinCC (TIA Portal) Runtime Advanced, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted packet to TCP port 2308. | |
| Modificada | Alta (7.8) | 0.55% | — | Siemens Simatic WinccSiemens Simatic PCS 7 | 22/7/2010 | 16/6/2026 | Siemens Simatic WinCC and PCS 7 SCADA system uses a hard-coded password, which allows local users to access a back-end database and gain privileges, as demonstrated in the wild in July 2010 by the Stuxnet worm, a different vulnerability than CVE-2010-2568. |